DrayTek VigorSwitch Multiple Models Path Traversal via getSyslogFile
Summary
| CVE | CVE-2026-71932 |
|---|---|
| State | PUBLISHED |
| Assigner | VulnCheck |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-24 18:17:17 UTC |
| Updated | 2026-08-26 17:08:22 UTC |
| Description | Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal sequences to access arbitrary files on the device. Exploitation requires valid administrative credentials for the device's web management interface. |
Risk And Classification
Primary CVSS: v4.0 6.9 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.006930000 probability, percentile 0.502990000 (date 2026-08-27)
Problem Types: CWE-22 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
| 3.1 | [email protected] | Secondary | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 4.9 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | DrayTek Corporation | VigorSwitch G2540xs | affected 3.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2540xs | affected 3.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch FX2120 | affected 3.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2282x | affected 2.10.6 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2282x | affected 2.10.6 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch Q2300x | affected 2.10.7 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch PQ2300xb | affected 2.10.7 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2542x | affected 3.10.6 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2542x | affected 3.10.6 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2542xh | affected 3.10.6 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch PX2060 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G1280 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P1280 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P1281x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G1282 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P1282 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2121 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2121 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch PQ2121x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch Q2121x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2280x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2280x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch Q2200x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch PQ2200xb | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2100 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2100 | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch G2540x | affected 2.9.10 custom | Not specified |
| CNA | DrayTek Corporation | VigorSwitch P2540x | affected 2.9.10 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.vulncheck.com/advisories/draytek-vigorswitch-multiple-models-path-traversal... | [email protected] | www.vulncheck.com | |
| www.draytek.com/about/security-advisory/multiple-vulnerabilities-in-vigorswit... | [email protected] | www.draytek.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jincheng Wang (@winmt) (en)
CNA: Le Yu (Nanjing University of Posts and Telecommunications) (en)
CNA: Xiapu Luo (The Hong Kong Polytechnic University) (en)